Vulnerabilities/

Cross site scripting Vulnerability in backstage Software Catalog

Severity:
Medium

Description

This vulnerability allows a malicious actor with access to add or modify content in an instance of the Backstage software catalog to inject script URLs in the entities stored in the catalog. If users of the catalog then click on said URLs, that can lead to an XSS attack.

Recommendation

Update the @backstage/catalog-model package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@backstage/catalog-model
Anything's wrong? Let us know Last updated on February 14, 2023